Great minds think alike :) Thanks Carlos & Pratik. I just applied the patch
and will restart the fuzzer.

On Wed, Oct 3, 2018 at 11:37 AM Pratik Vyas <[email protected]> wrote:

> * Greg Steuck <[email protected]> [2018-10-03 10:56:28 -0700]:
>
> >Hi Mike,
> >
> >I'm getting core files from vmds. Here's the most recent one. Should I
> >start collecting more stack traces and sending them to you?
> >
> >ci-openbsd$ doas /usr/local/bin/egdb /syzkaller/src/usr.sbin/vmd/obj/vmd
> >/var/crash/vmd/89501.core
> >Reading symbols from /syzkaller/src/usr.sbin/vmd/obj/vmd...done.
> >[New process 178128]
> >[New process 294426]
> >[New process 350865]
> >Core was generated by `vmd'.
> >Program terminated with signal SIGSEGV, Segmentation fault.
> >#0  0x00000c07a64148bd in virtio_shutdown (vm=0xc09e1418000) at
> >/syzkaller/src/usr.sbin/vmd/virtio.c:2018
> >2018            vioscsi->file.close(vioscsi->file.p, 0);
>
> Hi Greg,
>
> this is interesting.  Are you using the cdrom?  I guess not.  There
> seems to be no if condition around that statement.
>
> This diff should prevent that segfault.
>
> --
> Pratik
>
>
> Index: usr.sbin/vmd/virtio.c
> ===================================================================
> RCS file: /home/pdvyas/cvs/src/usr.sbin/vmd/virtio.c,v
> retrieving revision 1.70
> diff -u -p -a -u -r1.70 virtio.c
> --- usr.sbin/vmd/virtio.c       28 Sep 2018 12:35:32 -0000      1.70
> +++ usr.sbin/vmd/virtio.c       3 Oct 2018 18:35:40 -0000
> @@ -2015,7 +2015,8 @@ virtio_shutdown(struct vmd_vm *vm)
>         int i;
>
>         /* ensure that our disks are synced */
> -       vioscsi->file.close(vioscsi->file.p, 0);
> +       if (vioscsi != NULL)
> +               vioscsi->file.close(vioscsi->file.p, 0);
>         for (i = 0; i < nr_vioblk; i++)
>                 vioblk[i].file.close(vioblk[i].file.p, 0);
>  }
>


-- 
nest.cx is Gmail hosted, use PGP for anything private. Key:
http://goo.gl/6dMsr
Fingerprint: 5E2B 2D0E 1E03 2046 BEC3  4D50 0B15 42BD 8DF5 A1B0

Reply via email to